A municipal Windows host can open admin shares on peer systems using stolen user credentials. How should that pattern be framed in findings?
Select an answer to reveal the explanation.
Short Explanation
If one stolen user password waltzes you onto peer admin shares, that is the story: reuse plus overly trusting peer access. Frame it as a lateral-movement risk theme, not a how-to guide. The client needs the pattern and the impact, not a recipe book.
Full Explanation
Credential reuse that unlocks administrative shares on peer hosts is a classic lateral-movement finding class. Reporting should emphasize the risk theme and business impact without providing exploitation recipes. It is not a cosmetic logging issue, nor should credentials be published. CPTS-oriented writeups describe the pattern and remediation direction at a judgment level.